0c9aa10f41
_default_spawn() called build_subprocess_env(scrub_secrets=is_multiplex_active()) with no profile secret scope installed. Under multiplex, any name registered via terminal.env_passthrough makes _filter_secret_env's resolve_passthrough_value() call get_secret() with no scope active, which fails closed with UnscopedSecretError -- crashing every Kanban worker spawn, for every profile, as soon as env_passthrough is configured anywhere. Mirror _resolve_worker_cli_toolsets's existing scope-then-read ordering a few functions up in the same file: resolve the assignee's HERMES_HOME first, install build_profile_secret_scope() around the env build, then set env["HERMES_HOME"] from the value already resolved instead of calling resolve_profile_env() twice. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>